The Containment Era is here. →Explore

Executive Summary

In late 2025, the Advanced Persistent Threat (APT) group known as ToddyCat launched a sophisticated cyber espionage campaign targeting corporate environments across Europe and Asia. The attackers leveraged a new custom tool, TCSectorCopy, to steal Microsoft Outlook emails and Microsoft 365 OAuth 2.0 access tokens. By compromising user endpoints and abusing browser-based authentication flows, ToddyCat successfully exfiltrated sensitive email data and bypassed perimeter controls. The campaign, marked by its stealthy techniques, enabled attackers to maintain persistent access and move laterally within affected networks, significantly increasing the risk to sensitive enterprise communications and intellectual property.

This incident highlights the growing reliance of threat actors on token theft and cloud-based attack vectors, posing new challenges for organizations with hybrid or cloud-first environments. It underscores the urgent need for advanced detection capabilities, Zero Trust network segmentation, and comprehensive identity protection strategies to counter emerging APT tactics.

Why This Matters Now

Token-based and email compromise attacks are escalating, exploiting hybrid and cloud authentication gaps. Today’s security programs must address lateral attacker movement and credential/token theft, given rapid cloud adoption and the sophistication of modern APTs like ToddyCat.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The breach exposed critical gaps in cloud email and identity security, highlighting the need for encrypted traffic, segmentation, and ongoing anomaly detection to meet compliance mandates like HIPAA and PCI.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Applying CNSF controls such as Zero Trust Segmentation, egress policy enforcement, inline threat detection, and end-to-end encryption could have detected, prevented, or restricted attacker movement and exfiltration at several kill chain stages. These measures reduce lateral movement, enforce least privilege, enhance visibility, and block the exfiltration of sensitive data.

Initial Compromise

Control: Threat Detection & Anomaly Response

Mitigation: Early detection of malicious sign-in or anomalous authentication attempts.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Enforced least-privilege boundaries, limiting the blast radius of compromised credentials.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Detects and blocks unauthorized internal connections between workloads.

Command & Control

Control: Cloud Firewall (ACF) with Inline IPS

Mitigation: Blocks known bad command and control signatures and unexpected outbound communications.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Prevents sensitive data from being exfiltrated via unauthorized outbound flows.

Impact (Mitigations)

Delivers rapid visibility and alerts on breaches, limiting business and reputational damage.

Impact at a Glance

Affected Business Functions

  • Email Communications
  • Data Security
  • IT Operations
Operational Disruption

Estimated downtime: 5 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Unauthorized access to corporate email data, including sensitive communications and potential exposure of confidential information.

Recommended Actions

  • Implement zero trust segmentation and least privilege access policies across cloud workloads and users.
  • Enforce robust egress filtering to detect and block data exfiltration and command & control outbound communications.
  • Deploy inline threat detection and anomaly response to monitor for suspicious authentication and lateral movement.
  • Encrypt all data-in-transit—including internal flows—with high-performance traffic encryption (MACsec, IPsec) to prevent interceptor-based attacks.
  • Enhance centralized multicloud visibility to accelerate detection, investigation, and response to breaches targeting SaaS and cloud resources.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image